Identity DNS is VeilNet's decentralized DNS service that enables you to address Conflux instances using human-readable DNS names instead of IP addresses. Unlike traditional DNS systems that rely on centralized registries, Identity DNS operates entirely within VeilNet's Anchor Protocol control plane, providing enhanced security, privacy, and resilience.
Identity DNS does not require a centralized DNS registry. Instead, DNS name resolution is handled directly by the Anchor Protocol's control plane, which means:
Because Identity DNS operates within the Anchor Protocol control plane, it inherits all of Anchor's security properties:
Identity DNS enables powerful networking capabilities:
| Feature | Traditional DNS | Identity DNS |
|---|---|---|
| Architecture | Centralized registry | Decentralized, within Anchor Protocol |
| Security | Plaintext queries, external exposure | Encrypted, post-quantum secure |
| Privacy | Query metadata visible to DNS servers | No metadata leakage, private resolution |
| Dependencies | External DNS infrastructure required | Self-contained within VeilNet |
| Access Control | Limited or none | Team-based, fine-grained control |
| Load Balancing | Requires external services | Built-in, automatic |
dev-database.veilnet instead of IP addressesIdentity DNS provides significant security advantages over traditional DNS: